The Good, the Bug and the Ugly - Dissecting a USB n-Day in the Linux Kernel
Ferdinand Jarisch, Moritz Buhl
It remains a booming business to sell exploitation of 0-days to governmental law-enforcement agencies, mainly to catch bad guys. Sometimes, however, these capabilities are not-so-lawfully misused against other actors, such as activists.
Building on a report of Amnesty International's Security Lab, we investigate one such misuse that utilized several 0-days in the USB-stack of an Android phone's Linux kernel, connect the dots between device logs, CVE entries and Kernel source code, and create a working and portable exploit for affected Linux Kernels ourselves.